Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack
ID: 43fc69cb-585e-53bc-b67e-90aff9aa678d
STIX ID: report--43fc69cb-585e-53bc-b67e-90aff9aa678d
Feed Name: cybersecurityNews.com
**Executive Summary:** The Telnyx Python SDK on PyPI was compromised by the threat actor TeamPCP—malicious releases (telnyx 4.87.1 and 4.87.2) were published and execute at import time, using WAV steganography to deliver platform-specific payloads that establish persistence, harvest secrets, and exfiltrate data to 83.142.209.203:8080; the advisory places this incident within a broader credential-chaining supply-chain campaign that has previously backdoored Trivy, npm packages, Checkmarx GitHub Actions, and LiteLLM. The report includes package SHA256 hashes, C2 IP/URLs, persistence artifacts, and actionable mitigations (remove malicious versions, rotate credentials, block outbound traffic to the C2, and audit CI/CD pipelines).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
